Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49643

17
FAUCET Score

CVE-2022-49643 is a medium-severity integer overflow vulnerability (CWE-190) affecting the Linux kernel, specifically within the ima_appraise_measurement function when the ima-modsig is enabled. This local vulnerability (AV:L) has low attack complexity (AC:L) and requires low privileges (PR:L), potentially leading to high availability impact (A:H) but no confidentiality or integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.4, < 5.4.207CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.132CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.56CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.18.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
5.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:5.19:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
18.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 73rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-611.5.1.el9_7
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49643Moderate

kernel: ima: Fix a potential integer overflow in ima_appraise_measurement

Feb 26, 2025

References

git.kernel.org / stable/c/388f3df7c3c8b7f2a32b9ae0a9b2f9f6ad3b1b77
Patch
git.kernel.org / stable/c/640cea4c2839a821adfbb703b590a5928abe9286
Patch
git.kernel.org / stable/c/831e190175f10652be93b08436cc7bf2e62e4bb6
Patch
git.kernel.org / stable/c/c8d5d81940938b5f6c0f495ca9538e7740416f30
Patch
git.kernel.org / stable/c/d2ee2cfc4aa85ff6a2a3b198a3a524ec54e3d999
Patch